RadiusNest › Guides

MikroTik hotspot: "RADIUS server is not responding" and how to fix it

Last updated: 2 October 2026

Two messages cover most failed hotspot logins when users are checked by RADIUS. "RADIUS server is not responding" means the router got no answer at all. "Invalid username or password" means it got an answer, and the answer was no.

First: which message?

MessageMeaningLook at
RADIUS server is not respondingNo reply arrived in timeaddress, ports, firewall, source address, timeout, and the secret
invalid username or passwordThe server refused, or RADIUS was never askeduse-radius, the user on the server, the secret, the login method

Read the counters

/radius print
/radius monitor 0 once

The number is the line from /radius print. Try a login, then run it again and see which counter moved:

  • requests stays at 0: the router is not asking this server. See steps 1 and 2.
  • timeouts goes up: requests leave, nothing comes back. See steps 3 to 6.
  • bad-replies goes up: an answer came but could not be verified. The secret is wrong.
  • rejects goes up: the server said no. See step 7.
  • accepts goes up: RADIUS is fine; the problem is elsewhere.

1. The hotspot profile does not use RADIUS

/ip hotspot profile print
/ip hotspot profile set hsprof1 use-radius=yes

Check the profile that your hotspot server actually uses (/ip hotspot print shows it). Without use-radius=yes only users stored on the router can log in, and everyone else gets "invalid username or password".

2. The RADIUS entry is not for hotspot

/radius print detail
/radius set 0 service=hotspot disabled=no

In Winbox this is the row of tick boxes under Service. For a router that also runs PPPoE, tick both: service=hotspot,ppp.

3. Wrong address or ports

/radius set 0 address=203.0.113.10 authentication-port=1812 accounting-port=1813
/ping 203.0.113.10 count=4

1812 and 1813 are the standard ports. A ping that fails points to routing or the internet line, not to RADIUS. A ping that works proves only that the server is reachable, not that it answers RADIUS.

4. The secret does not match

The secret must be identical on both sides, including capitals and any space at the end. Depending on the server, a wrong secret shows as no answer, as bad-replies, or as a rejected password. Type it again on the router:

/radius set 0 secret="the-shared-secret"

5. The server does not know this router

A RADIUS server answers only clients it knows, usually by the address the request comes from. If the router has two internet lines or reaches the server through another interface, the request may arrive from an address the server does not expect, and it is silently ignored. Fix the source address on the router, or register the right one on the server:

/radius set 0 src-address=10.0.0.2

Use src-address=0.0.0.0 to let the router choose. With load balancing, make sure requests to the server always leave by the same line.

6. Firewall and timeout

The router sends the request itself, so it passes the output chain, and the reply comes back through input. A basic firewall that accepts established and related connections on input lets the reply in. Look for drop rules in output, and for UDP 1812 and 1813 being blocked on the way or on the server:

/ip firewall filter print where chain=output

The default wait for an answer is 300 ms, which is short for a server reached over the internet. Raise it:

/radius set 0 timeout=3s

7. The server answered no

  • The user does not exist, is disabled, or the password is wrong.
  • The package has ended or its data or time is used up.
  • The user is already online on as many devices as allowed.
  • The login page sends the password by CHAP and the server cannot check it that way. Allow PAP as well:
/ip hotspot profile set hsprof1 login-by=cookie,http-chap,http-pap

Read the log

/system logging add topics=radius,debug
/log print where topics~"radius"

You see each request sent, to which address, and the reply or the timeout. Remove the logging rule when you are done; it is noisy:

/system logging remove [find topics~"radius"]

The clock

RADIUS itself does not depend on the router clock. But the times in the log do, and comparing the router's log with the server's is how you find the request that went missing. Set System → Clock and the NTP client.

Background: how RADIUS works with MikroTik and the attributes in a reply.

Where RadiusNest fits

With RadiusNest the router is connected with one pasted command that sets the address, secret, services and profile for you, and no public IP is needed on the router, which removes steps 1 to 5 as sources of error. A refused login is then a matter of the customer's package, which you and the customer can both see.

Start the free trial See pricing

Questions and answers

What does "RADIUS server is not responding" mean on MikroTik?

The router sent the login to the RADIUS server and no reply arrived within the timeout. The cause is the address, the ports, a firewall, the source address or the secret.

Why do I get "invalid username or password" when the password is right?

Either the hotspot profile does not have use-radius=yes, so only router users are checked, or the server refused: wrong secret, ended package, device limit, or a CHAP login the server cannot verify.

What is a good RADIUS timeout on MikroTik?

The default of 300 ms suits a server on the same network. For a server reached over the internet, 2 to 3 seconds avoids false timeouts.

Related guides

Start the free trial See pricing